CVE-2025-66376: Zimbra Email Theft via Zero-Click Flaw
Russian hackers exploit a Zimbra zero-click flaw to steal email data from organizations, using a combination of phishing attacks and the CVE-2025-66376 vulnerability.
Agentic remediation automates the mobilization phase of CTEM to eliminate vulnerability backlogs and achieve Shift Zero by enabling autonomous, low-risk fixes under human supervision.
Russian hackers exploit a Zimbra zero-click flaw to steal email data from organizations, using a combination of phishing attacks and the CVE-2025-66376 vulnerability.
Check Point's SmartConsole GUI admin panel has a zero-day flaw, tracked as CVE-2026-16232, allowing unauthenticated attackers to obtain an application login token with administrator privileges.
Vibe-coded apps are found to be riddled with exploitable security flaws, with 434 issues discovered in a recent study, highlighting the need for improved security measures in AI-assisted development.
The US government warns of Iranian hackers targeting industrial control systems made by Siemens, Schneider Electric, and Rockwell Automation, highlighting the need for proactive defenses.
The FakeGit campaign has pushed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over 14 million downloads, by using a technique called 'agentbaiting' to increase visibility to AI agents.
A self-propagating malware strain, Sandworm_Mode, is targeting AI coding assistants and software developers' automated workflows, spreading through code repositories with minimal detection.
Seven out of 10 federal cyber regulations require duplicative written reports to federal agencies, according to a Government Accountability Office report.
The White House has accused a Chinese company of distilling Anthropic's Fable model to create their own AI product, sparking concerns over intellectual property theft.
Enterprise GenAI can increase the speed and scale of ransomware attacks if not properly governed, as it amplifies techniques attackers already use.